September 10, 2026·6 min read·AIgentic.media

Secret AI Downgrades in the US-China War

policy-regulationchinaus-governmentai-safetyai-model-security
Secret AI Downgrades in the US-China War

In September 2026, three US intelligence agencies asked American AI companies to do something that sounds like a spy movie plot: identify which of your users might be Chinese AI developers, and silently give them dumber answers.

The recommendation came in a joint statement from the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation. They named six Chinese AI companies . DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI . accusing them of waging "industrial-scale" distillation campaigns against US frontier models including Claude, GPT, Gemini, and Grok.

The proposed countermeasures go beyond simple account blocking. The agencies want AI companies to adopt what amounts to a secret tiering system: users suspected of being connected to Chinese AI firms should be quietly switched to less capable models, have their responses degraded, and receive no notification that anything changed.

"Lower prediction precision and business usefulness" is an acceptable trade-off, the agencies wrote.

The accusation

The joint statement represents the Trump administration's most detailed public accusation yet against Chinese AI companies. Dating the alleged theft to late 2024, the agencies said the Chinese firms "likely" acted with "Chinese government awareness" when extracting model capabilities.

The six named firms cover the spectrum of China's AI industry. DeepSeek, which recently made waves with its open-weight models, was accused of "extensive malicious distillation" targeting Claude, Gemini, GPT, and Grok to reduce its compute and research costs. Moonshot AI allegedly switched between models from leading US firms to distill fine-tuning techniques, reinforcement learning, and software engineering capabilities. Alibaba, MiniMax, StepFun, and Z.AI focused on particular models from Anthropic and OpenAI.

The techniques described in the statement read like a taxonomy of model security failures. Chinese firms allegedly used bulk purchases of fake accounts to execute "highly coordinated queries featuring identical or similar prompt texts," ranging from thousands to millions of queries on similar topics. They employed prompt injection to jailbreak models, including "prompts forcing models to reveal their hidden chain-of-thought reasoning." DeepSeek in particular was accused of instructing models to "imagine and articulate the internal reasoning behind completed responses."

The proposed solution: secret model downgrades

The agencies' recommended response has two layers. First, detection: AI companies should improve monitoring for "anomalous and malicious prompts, accounts, networks, and behaviors." They should flag accounts with suspicious subscription-to-usage ratios and new accounts immediately hitting maximum usage . both signs of "bulk deployment with pre-engineered templates."

Second, response: when suspected distillation is flagged, companies should "subtly" alter responses. The recommendations include presenting "correct information with different reasoning," adding stylistic inconsistencies, reducing reasoning depth, or secretly switching malicious accounts to an inferior model . all without providing any notice.

The agencies acknowledged that Chinese firms have automated quality assurance systems that detect when outputs are degraded. Some can automatically detect when a smarter model is available and switch within 24 hours. This creates an arms race dynamic: the US firms degrade outputs, the Chinese firms detect the degradation and adapt.

There is also the uncomfortable question of collateral damage. The agencies admitted that legitimate users might be caught in the policing frenzy, switched to a dumber model without receiving any alert. Users will likely notice if outputs degrade . exactly like the backlash OpenAI faced last year when its automatic routing system "consistently defaulted to less capable variants unless users explicitly added phrases like 'think harder.'"

China pushes back

Beijing rejected the accusations immediately. Foreign Ministry spokesperson Mao Ning called the charges "groundless" and said the US should focus on strengthening AI cooperation rather than operating smear campaigns. A Chinese Embassy spokesperson accused the Trump administration of running a campaign rooted in prejudice.

The timing is notable. The accusation lands just two weeks before a scheduled meeting between President Trump and Chinese President Xi Jinping on September 24 . and alongside a Ministry of Industry and Information Technology plan to "sharply expand the country's intelligent computing capacity over the next five years."

Treasury Secretary Scott Bessent reinforced the message, telling the South China Morning Post that China "can never get ahead" of the US in AI, framing the allegations as part of a broader strategy to maintain American technological primacy.

The deeper tension

The story here is not really about whether Chinese firms copied US models . that question is impossible to adjudicate from outside the companies. What matters is the structural tension between security and access that the agencies' recommendations reveal.

Model distillation is not inherently nefarious. It is a standard research technique that many open-weight models explicitly support. The largest AI companies train on synthetic data generated by other models as a matter of routine. What the US agencies are calling theft is, from a technical perspective, indistinguishable from normal API usage patterns . just at much higher volume.

The proposed solution amplifies this tension. Secret model downgrading requires AI companies to build exactly the kind of infrastructure critics have warned about: a surveillance system that profiles users and silently alters their experience based on opaque threat assessments. The agencies acknowledge the risk of false positives catching legitimate users.

And even if the technical measures work perfectly against state-backed Chinese firms, they set a precedent. Once the infrastructure exists to secretly downgrade any user based on an intelligence assessment, nothing prevents that same infrastructure from being used for other purposes. The bouncer at the door decides who gets the smart answers . and nobody tells the ones who don't.

Sources

Want to learn more?

Let's discuss how AI can transform your business.

Get in Touch